4 ms·
> How would you improve its security over what's there now? Automated builds on NPM servers based on code in public repos, like Docker has (had?). The least th
by dmitryminkovsky 5y ago
> How would you improve its security over what's there now?
Automated builds on NPM servers based on code in public repos, like Docker has (had?). The least they could do is require packages to be signed.
- junon 5y agoHow exactly does that help?
- potatoz2 5y agoControlled builds based on public repos prevents a malicious person (original author or not) from invisibly pushing a packages that doesn’t correspond to public sources. Signing packages prevents account takeovers from publishing bad packages. The remaining security problem is the author themselves coupled with too few eyes on public repos.
- junon 5y agoI fail to see how controlled builds would have prevented Marak pushing a patch release that broke everyone. Most malicious package activity I've seen has been at the hands of the original maintainers to begin with. The last thing can't be solved technologically.